Repository navigation
build: add nebula.release versioning and dependency locking - #68
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (6)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 SummarySummary by CodeRabbit
WalkthroughThe build now enables dependency locking for the buildscript classpath and conditionally for resolvable subproject configurations. New lockfiles record dependency versions and empty configurations. Lockfile files use LF line endings. ChangesDependency Locking
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~12 minutes Change: Other Merge Risk: ⚪ Minimal · up to No actionable merge-blocking behavior is established in the reviewed changes. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to Default dependency locking constrains version drift without introducing a demonstrated increase in execution or publication privileges. No introduced security defect was established. Release-build enforcement and interrupted or concurrent lock refresh remain unverified, so the assessment retains limited uncertainty. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Warning Some tools did not complete. Review the errors below. 🔧 OSV Scanner (2.6.0)buildscript-gradle.lockfileOSV Scanner exited with code 128 without a usable report Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks the locks at dawn, Comment |
4ae7c93 to
c305ae6
Compare
|
#72 targets this branch and proposes keeping the dependency locking while dropping nebula.release, with the reasoning in its description: the community's Maven-published repos all version from a hand-edited SNAPSHOT that Jenkins publishes, and nebula would change what master publishes. If that lands here, this PR still needs a rebase onto master and |
Terasology, gestalt and this repo all version from a hand-edited SNAPSHOT string that Jenkins publishes from long-lived branches. nebula.release would make CrashReporter the one Maven-published repo versioned from git tags, and a plain `publish` on master would ship `5.2.0-dev.N+sha` in place of today's `5.2.0-SNAPSHOT`. Locking stands on its own. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Seen on a Windows clone with `core.autocrlf=true`: every `--write-locks` left `buildscript-gradle.lockfile` flagged modified with an empty diff, because Gradle emits LF and Git expected CRLF. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
84ef6e5 to
11f5ff3
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The advertised nebula.release plugin is not applied, leaving tag-driven versioning unavailable.
Review effort: Balanced
Findings: None
What changed in this PR
Adds dependency locking and intends to introduce tag-driven release versioning.
Changes:
- Enables dependency locking for buildscript and subprojects.
- Adds generated lockfiles and a
-PnoLockescape hatch. - Enforces LF endings for lockfiles.
| File | Description |
|---|---|
build.gradle.kts |
Configures dependency locking. |
buildscript-gradle.lockfile |
Locks buildscript dependencies. |
cr-core/gradle.lockfile |
Locks core dependencies. |
cr-destsol/gradle.lockfile |
Locks Destination Sol dependencies. |
cr-terasology/gradle.lockfile |
Locks Terasology dependencies. |
.gitattributes |
Enforces LF lockfiles. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Cervator
left a comment
There was a problem hiding this comment.
Last copilot comment argues about the title of the PR after a pivot to just doing locking. Seems fine for that part.
Adds the same versioning/locking setup TerasologyLauncher already uses.
nebula.release21.0.0 for git-tag-driven versioning. This project already tags releases asvX.Y.Z(v5.1.0latest), matching the plugin's default tag convention, so no extratagStrategyconfig is needed.activateDependencyLocking()on the buildscript classpath), producingbuildscript-gradle.lockfile.dependencyLocking { lockAllConfigurations() }on every subproject (cr-core,cr-destsol,cr-terasology), each with its owngradle.lockfile— locking is per-project, so a single shared lockfile isn't how Gradle does this for a multi-project build. The root project has no resolvable configurations of its own beyondbuildscript, so it only gets the buildscript lockfile.-PnoLockescape hatch as the launcher: passing it skipsdependencyLocking{}entirely for that build, letting every range resolve fresh against whatever satisfies it right now — useful for trying an update locally before committing to it via--write-locks.Test plan:
./gradlew build -x testsucceeds with locking active./gradlew dependencies --write-locks(root) and./gradlew :cr-core:dependencies :cr-destsol:dependencies :cr-terasology:dependencies --write-locks(subprojects)